VYPR

CWE-284

Improper Access Control

PillarIncomplete

Description

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-19 · CAPEC-441 · CAPEC-478 · CAPEC-479 · CAPEC-502 · CAPEC-503 · CAPEC-536 · CAPEC-546 · CAPEC-550 · CAPEC-551 · CAPEC-552 · CAPEC-556 · CAPEC-558 · CAPEC-562 · CAPEC-563 · CAPEC-564 · CAPEC-578

CVEs mapped to this weakness (6,523)

page 274 of 327
  • CVE-2017-20199LowAug 16, 2025
    risk 0.13cvss 3.1epss 0.00

    A vulnerability was found in Buttercup buttercup-browser-extension up to 0.14.2. Affected by this vulnerability is an unknown functionality of the component Vault Handler. The manipulation results in improper access controls. The attack may be performed from a remote location. A…

  • CVE-2024-39361LowJul 3, 2024
    risk 0.13cvss 3.1epss 0.00

    Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can…

  • CVE-2022-25831LowApr 11, 2022
    risk 0.13cvss 2.0epss 0.00

    Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical attackers to access secured data in certain conditions.

  • CVE-2026-61047LowJul 21, 2026
    risk 0.12cvss 1.9epss 0.00

    Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure…

  • CVE-2025-43712LowJul 25, 2025
    risk 0.12cvss 2.9epss 0.00

    JHipster before v.8.9.0 allows privilege escalation via a modified authorities parameter. Upon registering in the JHipster portal and logging in as a standard user, the authorities parameter in the response from the api/account endpoint contains the value ROLE_USER. By…

  • CVE-2022-41659LowNov 14, 2023
    risk 0.12cvss 1.9epss 0.00

    Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2026-33415LowMar 31, 2026
    risk 0.11cvss 2.7epss 0.00

    Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from…

  • CVE-2025-14082LowDec 10, 2025
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in Keycloak Admin REST (Representational State Transfer) API. This vulnerability allows information disclosure of sensitive role metadata via insufficient authorization checks on the /admin/realms/{realm}/roles endpoint.

  • CVE-2024-40884LowAug 22, 2024
    risk 0.11cvss 2.7epss 0.00

    Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.

  • CVE-2024-41926LowAug 1, 2024
    risk 0.11cvss 2.7epss 0.00

    Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another…

  • CVE-2024-32969LowMay 23, 2024
    risk 0.11cvss 2.7epss 0.00

    vantage6 is an open-source infrastructure for privacy preserving analysis. Collaboration administrators can add extra organizations to their collaboration that can extend their influence. For example, organizations that they include can then create new users for which they know…

  • CVE-2024-4198LowApr 26, 2024
    risk 0.11cvss 2.7epss 0.01

    Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes which allows an attacker authenticated as team admin to demote users to guest via crafted HTTP requests.

  • CVE-2024-4195LowApr 26, 2024
    risk 0.11cvss 2.7epss 0.01

    Mattermost versions 9.6.0, 9.5.x before 9.5.3, and 8.1.x before 8.1.12 fail to fully validate role changes, which allows an attacker authenticated as a team admin to promote guests to team admins via crafted HTTP requests.

  • CVE-2022-0824HigMar 2, 2022
    risk 0.11cvss 8.8epss 0.97

    Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2015-3306May 18, 2015
    risk 0.11cvss epss 0.97

    The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

  • CVE-2026-45154LowJun 1, 2026
    risk 0.10cvss 2.6epss 0.00

    Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from…

  • CVE-2025-9381LowAug 24, 2025
    risk 0.10cvss 1.6epss 0.00

    A security flaw has been discovered in FNKvision Y215 CCTV Camera 10.194.120.40. This affects an unknown part of the file /tmp/wpa_supplicant.conf. Performing manipulation results in information disclosure. The attack may be carried out on the physical device. The attack's…

  • CVE-2024-30261LowApr 4, 2024
    risk 0.10cvss 2.6epss 0.01

    Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.

  • CVE-2022-41874LowNov 10, 2022
    risk 0.10cvss 2.6epss 0.00

    Tauri is a framework for building binaries for all major desktop platforms. In versions prior to 1.0.7 and 1.1.2, Tauri is vulnerable to an Incorrectly-Resolved Name. Due to incorrect escaping of special characters in paths selected via the file dialog and drag and drop…

  • CVE-2015-2509Sep 9, 2015
    risk 0.09cvss epss 0.71

    Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted Media Center link (mcl) file, aka "Windows Media Center RCE Vulnerability."